The MIT license, README, and minimal Composer dependency set make the artifact easy to inspect. There is no security scanning or policy, and the repository shows no evidence of active support. Do not adopt this release as a new dependency.
18%
Total Score
100
61
75
The package has only one release, published more than 8 years ago, with no releases in the last 12 months. That is strong evidence of abandonment for a dependency.
The repository name does not match the package and its README does not mention the package, so the linked source may not belong to this release.
The repository has zero stars and forks and only one watcher. Popularity is not decisive, but these counters provide no supporting evidence of an active user community.
Composer is used for builds, which is appropriate, but no security-scanning tooling is present. This leaves a meaningful transparency gap for supply-chain maintenance.
The repository is not archived, but it was last pushed more than 8 years ago. This avoids an explicit archive signal while still indicating inactive maintenance.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
psr/log Version ~1.0 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.